{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/otto-fleet-manager/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-75112"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OTTO Fleet Manager"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Rockwell Automation"],"content_html":"\u003cp\u003eRockwell Automation has disclosed a security vulnerability, identified as CVE-2026-75112, affecting the OTTO Fleet Manager software in versions V2.36.2 and earlier. The issue lies in the implementation of the bcrypt password hashing algorithm, which utilizes an insufficient work factor. This deficiency significantly lowers the computational effort required for an attacker to conduct offline brute-force attacks against stored password hashes. The threat is most relevant in scenarios where an attacker successfully obtains a copy of an unencrypted system backup. Because this vulnerability facilitates the compromise of credentials post-exfiltration, it represents a risk to the integrity of account access within industrial environments managed by this software.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could result in the compromise of user credentials stored within the OTTO Fleet Manager system. By reducing the computational cost of cracking hashes, attackers can more rapidly gain unauthorized access to the application, potentially impacting critical manufacturing and transportation systems where these units are deployed worldwide. The risk is limited to scenarios involving local or network access to unencrypted backup files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of OTTO Fleet Manager to version 2.36.3 or later to remediate the bcrypt work factor deficiency.\u003c/li\u003e\n\u003cli\u003eEnable encrypted system backups in OTTO Fleet Manager configuration as per the guidance in Rockwell Automation security advisory SD1791.\u003c/li\u003e\n\u003cli\u003eRestrict access to system backup files to highly privileged service accounts and implement robust monitoring to detect unauthorized file access or exfiltration.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate OTTO Fleet Manager instances from broader business networks, limiting the potential for lateral movement and access to sensitive backup data.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T16:05:45Z","date_published":"2026-08-27T16:05:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rockwell-otto-hash/","summary":"Rockwell Automation OTTO Fleet Manager versions V2.36.2 and earlier use an insufficient work factor for bcrypt password hashing, enabling attackers with access to system backups to perform efficient offline brute-force attacks.","title":"Insufficient Work Factor in Rockwell Automation OTTO Fleet Manager","url":"https://feed.craftedsignal.io/briefs/2026-08-rockwell-otto-hash/"}],"language":"en","title":"CraftedSignal Threat Feed - OTTO Fleet Manager","version":"https://jsonfeed.org/version/1.1"}